Serverless Phishing Kit on GitHub Targets Mexican Banks

2026-06-17T14:52:21Z57f7f8c65dd59d0fc79d8a8b1846fb6c35c178990fd9b25c73807c298ecee54a
agentjackingai-securitybackdoorcredential-theftgitbaitgithub-pagesjetbrains-pluginslaw-enforcementmalwarenpmphishingransomwareserverless-phishingsheetbestsupply-chainvulnerabilitieswordpresszero-day

What happened

A diverse set of Infosecurity Magazine stories highlights a surge in credential-theft and supply-chain attacks (GitBait serverless phishing using GitHub Pages/SheetBest, SniperDz PaaS, tampered OptinMonster WordPress plugins, malicious JetBrains plugins, npm security changes), multiple active malware families and backdoors (SprySOCKS, Rokarolla, SilabRAT, Vidar, AsyncRAT), and high-impact vulnerabilities and patches (Chrome CVE-2026-11645, Microsoft June fixes including three zero-days, critical phpBB and Check Point auth bypasses). AI-related risks feature prominently — large increases in员工上传

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
57f7f8c65dd59d0fc79d8a8b1846fb6c35c178990fd9b25c73807c298ecee54a
Enrichment time
2026-06-17T14:52:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Serverless Phishing Kit on GitHub Targets Mexican Banks · Baitaphish